build-macos-app

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several well-known and reputable external Swift and Node.js packages. These include 'convex' and 'convex-helpers' for backend integration, 'clerk-ios' and 'clerk-convex-swift' for authentication, and 'swift-snapshot-testing' for visual validation. All sources are established services and reputable organizations within the developer ecosystem.\n- [COMMAND_EXECUTION]: The skill includes a pre-commit hook and a typechecking script that execute standard Apple development tools such as 'xcodebuild', 'swift build', 'swiftlint', and 'swiftformat'. These commands are used as intended for a development-focused skill to ensure code quality and build integrity. The use of 'sudo' for downloading visionOS platform components is a documented requirement for Xcode management.\n- [SAFE]: No prompt injection attempts, data exfiltration patterns, or obfuscated content were detected. The skill follows best practices for secret management by advising the use of environment variables rather than hardcoding credentials. The auditing workflow poses no significant indirect prompt injection risk.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 03:52 PM
Security Audit — agent-trust-hub — build-macos-app